The first stable release of the PGP toolkit sq from the Sequoia project has been launched.

After seven years of development, the release of the command line tool sq 1.0 has been finalized, designed for working with OpenPGP artifacts. The tool has been prepared by the Sequoia PGP project, which is also developing a library of functions implementing the OpenPGP standard (RFC-4880). The 1.0 release is noted as the first stable release of the project, signifying the stabilization of the codebase and the cessation of changes that could disrupt compatibility. The code is written in Rust and is distributed under the GPLv2+ license.

The tool is included in the Red Hat Enterprise Linux 10 distribution as an alternative to GnuPG, utilized for PGP operations in the DNF and RPM package managers, and is used by default in the experimental branch of the APT package manager when Sequoia components are present in the system. The key server Hagrid, created by the Sequoia developers, is applied in the keys.openpgp.org service.

The Sequoia project was founded by three GnuPG developers from the company g10code, which specializes in auditing cryptosystems and developing extensions for GnuPG. The project's objective is stated as redesigning the architecture and implementing new techniques to enhance the security and reliability of the codebase. In addition to utilizing the Rust programming language to reduce the likelihood of memory errors, Sequoia has implemented additional error protection at the API level. For example, the API prevents accidental export of secret key material and safeguards against missing important actions when updating a digital signature. For further isolation, services working with open and closed keys are separated by individual processes.

In addition to functions for data encryption, working with digital signatures, and key management, similar to the capabilities of gpg, sq also provides a decentralized public key infrastructure (PKI). The PKI is used for authenticating certificates and messages, ensuring that the received public key and accepted messages are linked to the stated author and not generated by a malicious actor.

When loading a certificate from keys.openpgp.org or another key server, the sq utility will automatically save the certificate information on the local system and will use this information in subsequent operations to identify counterfeit certificates. It is noted that the implemented system can serve as a basis for creating a distributed certificate authority (CA) covering various key servers.

For example, before verifying the authenticity of the loaded OS Qubes builds, the user may first check the Qubes certificate provided by the main key server of the Qubes project: sq network search https://keys.qubes-os.org/keys/qubes-release-4.2-signing-key.asc

The specified command will download the certificate from the keys.qubes-os.org server and then check its presence on known key servers, such as keys.openpgp.org and keyserver.ubuntu.com, or will attempt to obtain it using the WKD (Web Key Directory) and DANE (DNS-Based Authentication of Named Entities) mechanisms. The utility will then compare the received certificates, and if they are associated with the same owner, it will suggest using the command 'sq pki link add' to save the certificate on the local system for subsequent checks. After saving, the certificate will be considered trusted, and to download the builds with their authenticity verified, it will be sufficient to execute the command: sq download --signature-url https://mirrors.edge.kernel.org/qubes/iso/Qubes-R4.2.3-x86_64.iso.asc --url https://mirrors.edge.kernel.org/qubes/iso/Qubes-R4.2.3-x86_64.iso --output /tmp/qubes.iso

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster